1、 我也没想到那么多弯弯绕绕的,看到评论区有提示,就照做了,编写url编码脚本,获取注入payload,测试回显位置。
#!/usr/bin/env python
# -*- coding:UTF-8 -*-
#time:2019/11/9 1:03
#author:White9527
from urllib import parse
import re
#查询语句
s1 = """order by 4"""
s2 = parse.quote(s1,"utf-8")
s3 = re.findall(r'.',s2)
j = 0
for i in s3:
if (s3[